Bug#825695: udd todo: List unsolved security issues in the TODO list?

2016-05-28 Thread Petter Reinholdtsen
ore aware of the unsolved issues. -- Happy hacking Petter Reinholdtsen

CVE-2012-5825 fixed in testing?

2016-01-15 Thread Petter Reinholdtsen
ing Petter Reinholdtsen

Is CVE-2014-0254 really affecting Qt and not only Windows?

2015-04-30 Thread Petter Reinholdtsen
-tracker.debian.org/tracker/CVE-2014-0254 -- Happy hacking Petter Reinholdtsen -- To UNSUBSCRIBE, email to debian-security-tracker-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org Archive: https://lists.debian.org/2fld22myv3s@diskless.uio.no

Re: Is CVE-2014-0254 really affecting Qt and not only Windows?

2015-04-30 Thread Petter Reinholdtsen
with the mail address. PErhaps the LTS list should be mentioned there? Not that I am unhappy with the speed of the reply. I believe it was very quick already. :) -- Happy hacking Petter Reinholdtsen -- To UNSUBSCRIBE, email to debian-security-tracker-requ...@lists.debian.org with a subject

Re: Audit of Debian/Ubuntu for unfixed vulnerabilities because of embedded code copies

2012-09-29 Thread Petter Reinholdtsen
to do so myself. :( If you want more direct feedback from me, we could meet on IRC to exchange knowledge. Otherwise, you can ask using email. -- Happy hacking Petter Reinholdtsen -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of unsubscribe. Trouble

Re: Audit of Debian/Ubuntu for unfixed vulnerabilities because of embedded code copies

2012-07-02 Thread Petter Reinholdtsen
assosiated with CVEs, to make it easier to figure out which Debian package are affected by a given CVE. Are you aware of my proposal to do this, mentioned on debian-security and also drafted on URL: http://wiki.debian.org/CPEtagPackagesDep ? -- Happy hacking Petter Reinholdtsen

Re: Audit of Debian/Ubuntu for unfixed vulnerabilities because of embedded code copies

2012-07-02 Thread Petter Reinholdtsen
to motivate people to provide CPE codes with the packages. -- Happy hacking Petter Reinholdtsen -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/20120702215911.gd32

Debian BTS report for CVE-2010-2941 (cups)

2010-11-13 Thread Petter Reinholdtsen
I just created URL: http://bugs.debian.org/603344 to track CVE-2010-2941 in BTS. You might want to add a reference to it from URL: http://security-tracker.debian.org/tracker/CVE-2010-2941 . Happy hacking, -- Petter Reinholdtsen -- To UNSUBSCRIBE, email to debian-security-tracker-requ

Re: When are security updates effective?

2006-09-01 Thread Petter Reinholdtsen
need to log out. So each users session need to keep track of when he logged in and check if some changes requiring a logout has happened since then. Should not be too hard, though. Friendly, -- Petter Reinholdtsen -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe

Re: SELinux

2005-09-21 Thread Petter Reinholdtsen
[David Pastern] Interesting question. Sadly, for a long, long while, the development process of Debian has been slower than a dead snail nailed to the floor. As a participant in that process, I have not had that experience. The inability, or indecision to actually include new technologies

Re: Bad press again...

2005-08-30 Thread Petter Reinholdtsen
[Frans Pop] IMO the status of the security team is not changed by that mail: if it was delegated before that time, it still is, and similar if it was not. Personally, I only find it reasonable that all groups in Debian with special privileges within the Debian community are delegates. It

Re: Bad press again...

2005-08-27 Thread Petter Reinholdtsen
[Florian Weimer] I don't think so. Joey seems to be satisfied with this situation, and apart from unanswered email messages to [EMAIL PROTECTED], there are few complaints, AFAIK. I'm not sure if the satisfaction of Martin Schulze is a good measuring stick to judge the quality of the stable

Re: Bad press again...

2005-08-27 Thread Petter Reinholdtsen
[Florian Weimer] Correct me if I'm wrong, but the current team doesn't seem to want new members. I've been told that the current stable security team consist of one person doing the work, Martin Schulze. If this team do not want new members, something strange is afoot. And prospective

Re: Bad press again...

2005-08-27 Thread Petter Reinholdtsen
[Martin F Krafft] And prospective security team members should start working in the testing security team. There are no need to keep secrets (all is done in public), Which doesn't address the problem that embargoed bugs are possibly handled suboptimally in Debian. And it does not address

security hole in sshd in oldstable?

2005-08-24 Thread Petter Reinholdtsen
Are there known security holes in sshd in oldstable (woody)? Yesterday, I was told that one of the machines I administrate were rooted, and that this was the springboard used to crack the reporters machine. He was told this on IRC by the person claiming to do the breakin. The person breaking in

Re: On Mozilla-* updates

2005-08-02 Thread Petter Reinholdtsen
[Noah Meyerhans] How about actually maintaining them? That's exactly what I think we should do. Is this we as in you, or we as in someone else? -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Debian Security Support in Place

2005-07-09 Thread Petter Reinholdtsen
[Martin Wodrich] IIRC security-support for sarge started befor its release. But only one month before the release. That depends on your definition of support. The testing security team was working hard to secure it a long time before sarge was released.

Re: Debian Security Support in Place

2005-07-09 Thread Petter Reinholdtsen
[Sven 'Rae the Git' Grounsell] Also, you are IMHO ignoring, that Debian is one of the _very_ few distros, that provides _seamless_ upgrades between even major releases. This is a slight exaggeration, as this do not really work very seamlessly for packages where the configuration was changed.

Re: Bad press related to (missing) Debian security - action

2005-06-29 Thread Petter Reinholdtsen
[Alvin Oga] i don't want any handholding ... other than access the the resources and info and/or question answer .. - in my case, i'd like to create test-sec.debian.org for which i cannot do anything about it unless i do get some handholding and it's purpse to supplement